CVE-2022-21742

EUVD-2022-26906
Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
twcertCNA
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
realtekrtl8156_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8156_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8156_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8156b_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8156b_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8156b_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8153_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8153_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8153_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8153b_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8153b_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8153b_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8154_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8154_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8154_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8154b_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8154b_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8154b_firmware
10.28 ≤
𝑥
< 10.50
realtekrtl8152b_firmware
7.42 ≤
𝑥
≤ 7.53
realtekrtl8152b_firmware
8.49 ≤
𝑥
≤ 8.60
realtekrtl8152b_firmware
10.28 ≤
𝑥
< 10.50
𝑥
= Vulnerable software versions